cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2068
Views
0
Helpful
1
Replies

Is cisco AMP support integration with SIEM?

RafikWassef
Level 1
Level 1

Is Cisco security support integration with any SIEM solution, if yes please update me with more details

1 Reply 1

Various SEIM products have ways to get events from AMP, but AMP can't push the events.

Logrhythm has a beat for their Open Collector to pull AMP events into the SEIM via the API. (its all based on elastic beats)
I think Splunk and QRadar both have something similar. Here's Cisco Doc for splunk
https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/215973-amp-for-endpoints-integration-with-splun.html

You may find some useful info and options in SecureX (dashboards/orchestration/incident managment/automated actions, etc.)